Version 2 · Last updated 2026-09-05
This addendum explains how personal data is handled in Starkie Teams, the company headshots product. It sits on top of our privacy policy, which continues to apply; where the two differ for Teams, this document wins. It is written for two audiences: the employees and contractors invited to a shoot ("members"), and the administrators who run an organisation.
The organisation that invited you decides that headshots are made and what happens to them, so it is the controller of your data; Starkie AI, [legal entity name, registered address, VAT number], operating from Italy, is its processor and handles your data on its instructions. For administrators' own account data we are the controller. The processor terms are published at /legal/dpa.
From a member: the name, work email address and optional job title your organisation entered when inviting you; the three to eight selfies you upload; the images generated from them; a branded profile picture if your organisation uses one; and your consent record — which version of the consent text you accepted, when, a hashed IP address and your browser's user agent. From an administrator: account and sign-in details, the organisation's settings, and billing information.
To train a private image model of your face, generate your headshots, deliver them to you and to your organisation's administrators, package downloads, and send the emails that go with all of that: your invitation, reminders, the notice that your photos are ready, and deletion confirmations. We also keep an audit log of privacy-relevant actions and monitor errors so the service works.
Your images are never used to train models for anyone else, and they are never sold or used for advertising. You give explicit consent before you can upload anything, and you can withdraw it by deleting your data.
You can, through the private link in your emails. Your organisation's owners and admins can see the headshots generated for their members, and where the organisation has turned approval on, an administrator reviews a member's photos before they are delivered. Nobody else has access: photos are stored privately and served only through links that expire, so there is no public URL for them. Inside Starkie, access is limited to what is needed to run and support the service.
Starkie Teams is not an EU-only service. Model training and image generation happen at Astria in the United States, images are stored in Amazon S3 in us-west-1, and email is sent through Resend in the United States. These transfers are covered by the European Commission's Standard Contractual Clauses. The full list is at /legal/subprocessors.
Your uploaded selfies are deleted a set number of days after your photos are ready — your organisation chooses between 7 and 90 days, 30 by default — and the model trained from them goes at the same time, unless your organisation has opted in to keeping it so you can retake without uploading again. The generated headshots stay available to you and your organisation until deleted.
You have the rights of access, rectification, erasure, restriction, portability and objection. In practice:
We keep a record of a data-subject request — its type, dates and outcome — for 24 months after it closes, to show we handled it; its personal content is redacted once the member it concerns is deleted.
You can complain to the supervisory authority where you live or work; in Italy, that is the Garante per la protezione dei dati personali.